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THIS LISTING OF CLAIMS WILL REPLACE ALL PRIOR VERSIONS, AND 
LISTINGS OF CLAIMS IN THE APPLICATION. 

LISTING OF CLAIMS: 

1 . (Original) A method of detecting unauthorized access attempts to a network, 
comprising: 

receiving a request from a user to obtain an address; 
obtaining said address; 

applying a function to said address to obtain a return address, said return address 
corresponding to a used one of a block of addresses; 
returning said return address to said user; 
monitoring access to said address; and 

detecting an unauthorized attempt to access said address when an attempted 
address corresponds to an unused one of said block of addresses. 

2. (Currently amended) The A-method according to claim 1, wherein applying said 
function comprises hashing a user address of said user to obtain one value of a range of 
values mapping to said block of addresses, said one value designating said used one of 
said block of addresses. 

3. (Currently amended) The A-method according to claim 2, wherein applying said 
function comprises hashing a time of said request. 

4. (Currently amended) The A-method according to claim 2, wherein detecting comprises 
tracing said user when said attempted address corresponds to said unused one of said 
block of addresses. 

5. (Currently amended) The A -method according to claim 4, comprising blocking 
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additional unauthorized attempts when said attempted address corresponds to said unused 
one of said block of addresses. 

6. (Currently amended) A method according to claim 4, wherein unused ones of said 
block of addresses correspond to attack detectors. 

7. (Currently amended) The A-method according to claim 1, wherein said function 
comprises hashing a time of said request to obtain one value of a range of values mapping 
to said block of addresses, said one value designating said used one of said block of 
addresses. 

8. (Currently amended) The A-method according to claim 1, wherein applying said 
function comprises changing said used one of said block of addresses over time. 

9. (Currently amended) The_A-method according to claim 8, wherein applying said 
function comprises determining a time period for changing said one of said block of 
addresses. 

10. (Currently amended) The A -method according to claim 9, wherein determinin g the a 
time period comprises using a pre-selected time period. 

11. (Currently amended) The A-method according to claim 9, wherein determining the a 
time period comprises generating a random time period. 

12. (Currently amended) The A -method according to claim 8, wherein changing said used 
one of said block of addresses comprises randomly choosing said used one from said 
block of addresses. 

13. (Currently amended) The A-method according to claim 8, wherein detecting 
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comprises tracing said user when said attempted address corresponds to said unused one 
of said block of addresses. 

14. (Currently amended) The A -method according to claim 13, comprising blocking 
additional unauthorized attempts when said attempted address corresponds to said unused 
one of said block of addresses. 

15. (Currently amended) The A-method according to claim 13, wherein unused ones of 
said block of addresses correspond to attack detectors. 

16. (Currently amended) The A-method according to claim 8, further comprising 
determining said attempt is authorized when a connection exists between said user and 
said unused address. 

17. (Currently amended) The A -method according to claim 8, wherein changing said used 
one of said block of addresses comprises coordinating changes in a name-to-address 
database and a host identity-to-address database. 

18. (Currently amended) The A-method according to claim 1, wherein detecting 
comprises tracing said user when said attempted address corresponds to said unused one 
of said block of addresses. 

19. (Currently amended) The A-method according to claim 18, comprising blocking 
additional unauthorized attempts when said attempted address corresponds to said unused 
one of said block of addresses. 

20. (Currently amended) The A-method according to claim 1, wherein unused ones of 
said block of addresses correspond to attack detectors. 
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21. (Original) A computer-readable medium containing instructions for controlling a 
processor to detect unauthorized access attempts to a network by: 

receiving a request from a user to obtain an address; 
obtaining said address; 

applying a function to said address to obtain a return address, said return address 
corresponding to a used one of a block of addresses; 
returning said return address to said user; 
monitoring access to said address; and 

detecting an unauthorized attempt to access said address when an attempted 
address corresponds to an unused one of said block of addresses. 

22. (Currently amended) The computer-readable medium of claim 21, further comprising 
instructions for controlling a-the processor to apply said function by hashing at least one 
of a user address of said user and a time of said request to obtain one value of a range of 
values mapping to said block of addresses, said one value designating said used one of 
said block of addresses. 

23. (Currently amended) The computer-readable medium of claim 21, further comprising 
instructions for controlling a-the processor to detect said unauthorized attempt by tracing 
said user when said attempted address corresponds to said unused one of said block of 
addresses. 

24. (Currently amended) The computer-readable medium of claim 23, further comprising 
instructions for controlling a-the processor to detect said unauthorized attempt by 
blocking additional unauthorized attempts when said attempted address corresponds to 
said unused one of said block of addresses. 

25. (Currently amended) The computer-readable medium of claim 21, further comprising 
instructions for controlling a-the processor to apply said function by changing said used 
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one of said block of addresses over time. 

26. (Currently amended) The computer-readable medium of claim 25, further comprising 
instructions for controlling a -the p rocessor to change said used one of said block of 
addresses over time by at least one of determining a time period using a pre-selected time 
period and determining a time period by generating a random time period. 

27. (Currently amended) The computer-readable medium of claim 25, further comprising 
instructions for controlling a-the processor to change said used one of said block of 
addresses by randomly choosing said used one from said block of addresses. 

28. (Currently amended) The computer-readable medium of claim 25, further comprising 
instructions for controlling a-the processor to determine said attempt is authorized by 
determining that a connection exists between said user and said unused address. 

29. (Currently amended) The computer-readable medium of claim 25, further comprising 
instructions for controlling a-the processor to change said used one of said block of 
addresses by coordinating changes in a name-to-address database and a host identity-to- 
address database. 

30. (Original) A system for detecting unauthorized access attempts to a network, 
comprising: 

means for receiving a request from a user to obtain an address; 
means for obtaining said address; 

means for applying a function to said address to obtain a return address, said 
return address corresponding to a used one of a block of addresses; 
means for returning said return address to said user; 
means for monitoring access to said address; and 

means for detecting an unauthorized attempt to access said address when an 



B3387764.1 



-6- 



Serial No. 10/826,897 
AttyDkt: 03-4024 



attempted address corresponds to an unused one of said block of addresses. 

31. (Original) The system of claim 30, wherein said means for applying further comprises 
means for hashing at least one of a user address of said user and a time of said request to 
obtain one value of a range of values mapping to said block of addresses, said one value 
designating said used one of said block of addresses. 

32. (Original) The system of claim 30, wherein said means for detecting further comprise 
means for tracing said user when said attempted address corresponds to said unused one 
of said block of addresses. 

33. (Original) The system of claim 32, wherein said means for detecting further comprise 
means for blocking additional unauthorized attempts when said attempted address 
corresponds to said unused one of said block of addresses. 

34. (Original) The system of claim 30, wherein said means for applying further comprise 
means for changing said used one of said block of addresses over time. 

35. (Original) The system of claim 34, wherein said means for changing further comprise 
at least one of means for determining a time period using a pre-selected time period and 
means for determining a time period by generating a random time period. 

36. (Original) The system of claim 34, wherein said means for changing further comprise 
means for randomly choosing said used one from said block of addresses. 

37. (Original) The system of claim 34, further comprising means for determining said 
attempt is authorized when a connection exists between said user and said unused 
address. 
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38. (Original) The system of claim 34, further comprising: 

a name-to-address database; 

a host identity-to-address database; and 

means for coordinating changes in said name-to-address database and said host 
identity-to-address database in conjunction with said means for changing. 

39. (Original) A computer program, disposed on a computer-readable medium, for 
enabling detection of unauthorized access attempts to a network, said computer program 
including instructions for causing a processor to: 

receive a request from a user to obtain an address; 
obtain said address; 

apply a function to said address to obtain a return address, said return address 
corresponding to a used one of a block of addresses; 
return said return address to said user; 
monitor access to said address; and 

detect an unauthorized attempt to access said address when an attempted address 
corresponds to an unused one of said block of addresses. 

40. (Currently amended) The computer program of claim 39, wherein said instructions 
for causing a-the processor to apply said function further include instructions for causing 
a processor to at least one of hash a user address of said user and hash a time of said 
request to obtain one value of a range of values mapping to said block of addresses, said 
one value designating said used one of said block of addresses. 

41. (Currently amended) The computer program of claim 40, wherein said instructions 
for causing a-the processor to detect further include instructions for causing a processor to 
trace said user when said attempted address corresponds to said unused one of said block 
of addresses. 
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42. (Currently amended) The computer program of claim 41, further including 
instructions for causing a-the processor to block additional unauthorized attempts when 
said attempted address corresponds to said unused one of said block of addresses. 

43. (Currently amended) The computer program of claim 41, further including 
instructions for causing a-the processor to correspond said unused ones of said block of 
addresses with attack detectors. 

44. (Currently amended) The computer program of claim 39, wherein said instructions 
for causing a-the processor to apply said function further include instructions for causing 
a processor to change said used one of said block of addresses over time. 

45. (Currently amended) The computer program of claim 44, wherein said instructions 
for causing a-the processor to apply said function further include instructions for causing 
a processor to at least one of use a pre-selected time period for changing said one of said 
block of addresses and generate a random time period for changing said one of said block 
of addresses. 

46. (Currently amended) The computer program of claim 44, wherein said instructions 
for causing a-the processor to change said used one of said block of addresses further 
include instructions for causing a processor to randomly choose said used one from said 
block of addresses. 

47. (Currently amended) The computer program of claim 44, wherein said instructions 
for causing a-the processor to detect further include instruction for causing a processor to 
trace said user when said attempted address corresponds to said unused one of said block 
of addresses. 

48. (Currently amended) The computer program of claim 47, further including 
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instructions for causing a-the processor to block additional unauthorized attempts when 
said attempted address corresponds to said unused one of said block of addresses. 

49. (Currently amended) The computer program of claim 47, further including 
instructions for causing a-the processor to correspond attack detectors with unused ones 
of said block of addresses. 

50. (Currently amended) The computer program of claim 44, further including 
instructions for causing a-the processor to determine said attempt is authorized when a 
connection exists between said user and said unused address. 

51. (Currently amended) The computer program of claim 44, further including 
instructions for causing a-the processor to coordinate said change in a name-to-address 
database and a host identity-to-address database. 

52. (Currently amended) The computer program of 39, wherein said instructions for 
causing a-the processor to detect further include instructions for causing a processor to 
trace said user when said attempted address corresponds to said unused one of said block 
of addresses. 

53. (Currently amended) The computer program of claim 52, further including 
instructions for causing a-the processor to block additional unauthorized attempts when 
said attempted address corresponds to said unused one of said block of addresses. 

54. (Currently amended) The computer program of claim 39, further including 
instructions for causing a-the processor to correspond attack detectors with unused ones 
of said block of addresses. 
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